CVE-2025-62707
BaseFortify
Publication date: 2025-10-22
Last updated on: 2025-10-27
Assigner: GitHub, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pypdf_project | pypdf | to 6.1.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-834 | The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in pypdf versions prior to 6.1.3 allows an attacker to craft a specially designed PDF containing a page with an inline image using the DCTDecode filter. When this PDF is parsed, it can cause the library to enter an infinite loop during content stream parsing.
How can this vulnerability impact me? :
The impact of this vulnerability is that processing a maliciously crafted PDF can cause the application using pypdf to hang or become unresponsive due to an infinite loop, potentially leading to denial of service.
What immediate steps should I take to mitigate this vulnerability?
Update pypdf to version 6.1.3 or later, as this version contains the fix for the infinite loop vulnerability caused by parsing PDFs with inline images using the DCTDecode filter.